<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User ID mapping works on DC but not/intermittent on branches for Intune internal users. in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-mapping-works-on-dc-but-not-intermittent-on-branches-for/m-p/1248039#M7282</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have a PA-1410 at DC (with GlobalProtect) and PA-440/410 at branches.&lt;BR /&gt;Microsoft Intune enrolled devices users authenticate via SAML-Azure AD, non-Intune users via LDAP on-prem AD. User-ID is learned on the DC firewall and redistributed to branches using existing redistribution profiles.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Working fine for:&lt;/P&gt;&lt;P&gt;Non-Intune internal/external network users&lt;/P&gt;&lt;P&gt;Intune users from external network (via GP)&lt;/P&gt;&lt;P&gt;Intune users on internal network at DC&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Issue:&lt;/P&gt;&lt;P&gt;Intune users on internal network at branch sites do not get User-ID mapping or it is intermittent.&lt;/P&gt;&lt;P&gt;In all cases, DC firewall is learning and redistributing the mappings.&lt;/P&gt;&lt;P&gt;Same design works at DC but not consistently at branches only for Intune internal users.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen this before?&lt;/P&gt;&lt;P&gt;Any pointers or real-world fixes would be really appreciated.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Feb 2026 12:18:03 GMT</pubDate>
    <dc:creator>abhishek.kumar</dc:creator>
    <dc:date>2026-02-12T12:18:03Z</dc:date>
    <item>
      <title>User ID mapping works on DC but not/intermittent on branches for Intune internal users.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-mapping-works-on-dc-but-not-intermittent-on-branches-for/m-p/1248039#M7282</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have a PA-1410 at DC (with GlobalProtect) and PA-440/410 at branches.&lt;BR /&gt;Microsoft Intune enrolled devices users authenticate via SAML-Azure AD, non-Intune users via LDAP on-prem AD. User-ID is learned on the DC firewall and redistributed to branches using existing redistribution profiles.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Working fine for:&lt;/P&gt;&lt;P&gt;Non-Intune internal/external network users&lt;/P&gt;&lt;P&gt;Intune users from external network (via GP)&lt;/P&gt;&lt;P&gt;Intune users on internal network at DC&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Issue:&lt;/P&gt;&lt;P&gt;Intune users on internal network at branch sites do not get User-ID mapping or it is intermittent.&lt;/P&gt;&lt;P&gt;In all cases, DC firewall is learning and redistributing the mappings.&lt;/P&gt;&lt;P&gt;Same design works at DC but not consistently at branches only for Intune internal users.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen this before?&lt;/P&gt;&lt;P&gt;Any pointers or real-world fixes would be really appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 12:18:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-mapping-works-on-dc-but-not-intermittent-on-branches-for/m-p/1248039#M7282</guid>
      <dc:creator>abhishek.kumar</dc:creator>
      <dc:date>2026-02-12T12:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: User ID mapping works on DC but not/intermittent on branches for Intune internal users.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-mapping-works-on-dc-but-not-intermittent-on-branches-for/m-p/1248197#M7285</link>
      <description>&lt;P&gt;When Intune users are at a branch, their traffic hits the local PA-440/410, but because they authenticate via SAML (Azure AD) rather than local AD, there are no security logs for a local User-ID agent to scrape. If the DC firewall is redistributing mappings based on a GlobalProtect inner-tunnel IP or a specific DC-centric subnet, those mappings won't match the local branch LAN IP of the device.&lt;/P&gt;&lt;P&gt;To fix this, ensure your Redistribution Filter includes the branch IP subnets and verify that the branch firewalls are configured as Log Receivers or have the DC firewall added as a User-ID Agent. Additionally, since Intune devices often use randomized MAC addresses or transition between Wi-Fi/Wired interfaces, consider deploying the Palo Alto GlobalProtect app in "Internal Gateway" mode; this forces the client to report its current internal IP directly to the firewall, bypassing the need for unpredictable log scraping or redistribution lag.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Feb 2026 05:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-id-mapping-works-on-dc-but-not-intermittent-on-branches-for/m-p/1248197#M7285</guid>
      <dc:creator>dora745nevels</dc:creator>
      <dc:date>2026-02-16T05:53:34Z</dc:date>
    </item>
  </channel>
</rss>

